Privacy Policy

Last updated 27 July 2026

The short version

  • Your screen time never leaves your phone. Oath measures which apps you use and for how long, and that record stays in local storage on your device. It is not uploaded, not backed up to our servers, and we cannot see it.
  • What does leave your phone is what a Pact needs to work: your name and email from Google Sign-In, the rules you agree with your partner, and a record of when a rule was broken.
  • We do not sell your data, and Oath contains no advertising or analytics trackers.
  • Your partner sees less than you might expect. They are not told when you break a rule. Details in "What your partner can see".

Our contact details

Name: Immanuel Rajiv, trading as Way Studio — a sole trader based in the United Kingdom.
E-mail: waystudio.apps@gmail.com

For the purposes of UK data protection law we are the "controller" of the personal data described in this policy. This policy covers the Oath Android app (package com.waystudio.oath) and this website.

We are a sole trader and are not required to appoint a Data Protection Officer, so please send all data protection queries to the address above.

The type of personal information we collect

What stays on your phone only

The following is stored in a database on your device and is never transmitted to us or anyone else. If you uninstall Oath, it is deleted with the app.

Oath reads this information using Android's Usage Access permission, which you grant during setup and can withdraw at any time in your phone's settings.

What is sent to our servers

Oath uses Google Firebase to let two people share a Pact across two phones. Only the data below is sent.

DataWhy it is needed
Google account details Your display name, email address, profile photo URL, and a Google-issued user ID. Used to sign you in and to show your partner who they are paired with.
Notification token A Firebase Cloud Messaging token identifying your device, so your partner's phone can reach yours with a notification.
Pact and rule content The rules you and your partner agree: the rule name, the time limits and windows, and the package names of the apps you name in a rule (for example com.instagram.android). Both partners must see the same rules, so they are stored centrally.
Breach records When a rule was broken, which rule, the app that triggered it, and how it was resolved. Also any note you type when requesting a key, and any note your partner types when declining.
Partner linkage Which two accounts are joined in a Pact, and the short invite code used to join.
Subscription status Whether your account is in a trial or has an active subscription, verified with Google Play. We never see your card details; Google handles payment.

The third row is worth reading twice. We never receive your usage figures, but a rule you write does name the apps it governs, and a breach record names the app that triggered it. If you would rather an app was not named on our servers, keep it out of a shared rule.

How we get your personal information and why we collect it

Most of the personal information we process is provided to us directly by you, when you sign in with Google, when you write a rule, and when you send a note to your partner. We also receive information indirectly from two sources: Google Sign-In gives us your name, email address and profile photo URL when you authorise it, and Google Play tells us whether your subscription is active.

We use that information to create and run your account, to keep your Pact in step across two phones, to let your partner grant you a key, to send the notifications described below, and to confirm you are entitled to the paid features.

The Accessibility Service

Oath cannot block an app without Android's Accessibility Service, so we ask you to turn it on. It is a powerful permission, so here is the whole of what Oath does with it.

Oath also requests permission to see the list of apps installed on your device, so you can choose apps when writing a rule. That list is used on your device to draw the picker and is not uploaded.

Our lawful bases

Under the UK GDPR, the lawful bases we rely on for processing this information are:

What your partner can see

A Pact shows your partner less than most people expect. They can see:

Your partner is not sent a notification when you break a rule. Breaches are quiet by default. They are notified only when you ask them for a key, when you use a hammer to release yourself, when they decline a request, and when the Pact is paused, revived, or dissolved.

Your partner never sees your screen time figures, your app usage, your focus sessions, or any app you have not named in a shared rule.

Who we share your information with

We use a small number of processors, and we do not sell data to anyone.

We may also disclose data where the law requires it, or to protect our rights or someone's safety.

Cookies. This website sets no cookies and contains no analytics or advertising trackers. Your visit is not tracked. The Oath app sets no cookies either.

How we store your personal information

Your information is securely stored with Google Firebase, in the eur3 European multi-region (Belgium and the Netherlands). Access to our database is governed by server-side security rules that restrict every record to the people party to it, and sensitive operations run as server functions rather than being trusted to the app. Subscription entitlements are verified on our server, not on your phone. Requests are checked with Google Play Integrity to confirm they come from a genuine, unmodified copy of Oath.

Our database region is in the EEA. Google, as our processor, may transfer or access data outside the UK and EEA in the course of running its infrastructure and support. Where that happens, transfers are covered by the UK International Data Transfer Addendum or Standard Contractual Clauses.

We keep your information for the following periods, after which it is deleted from our database:

No service can promise perfect security, and we do not. If a breach occurs that puts your rights at risk, we will tell you and the ICO as the law requires.

Automated decision-making

We do not make automated decisions about you that produce legal effects or similarly significant effects, and we do not profile you.

Oath does apply your own rules automatically — when an app you named goes past a limit you agreed, that app is sealed without anyone reviewing it first. That is the function you asked for. It affects only that app, only on your own phone, and it is not used to judge you, score you, or decide anything about you beyond the rule you wrote.

Your data protection rights

Under data protection law, you have rights including:

You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.

Please contact us at waystudio.apps@gmail.com if you wish to make a request.

To delete your account and the data attached to it, see Deleting your account.

How to complain

If you have any concerns about our use of your personal information, you can make a complaint to us at waystudio.apps@gmail.com. We would rather you told us first so we can put it right.

You can also complain to the ICO if you are unhappy with how we have used your data.

The ICO's address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk

Children

Oath is not designed for children and is not directed at them. You must be at least 18 to use it. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will tell you in the app before it takes effect.